Skip to content

Commit e5bbe37

Browse files
authored
Add PII storage and PHI specification under Guides > Security > Application (#788)
* add PII storage and PHI specific line * add note about not sharing phi in conversations that may be captured or stored
1 parent c9a31c5 commit e5bbe37

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

‎security/application.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -137,8 +137,7 @@ sure the connection itself is secured using TLS.
137137

138138
## Personally-Identifying Information (PII)
139139

140-
As much as you can, do not touch any information you don't need. Some tricks for
141-
this:
140+
As much as you can, do not touch any information you don't need.
142141

143142
- Send any credit card data directly to the payment processor from the client.
144143
They'll give back a token, which you can store safely.
@@ -147,6 +146,7 @@ this:
147146

148147
When you must store PII:
149148

149+
- Store sensitive data in controlled systems with appropriate access restrictions and encryption. In particular, Protected Health Information (PHI) should not be stored in broad, shared tools such as Google Drive, Slack, or Figma, and should not be shared in conversations that may be recorded, transcribed, or summarized by tools, as it may be captured and stored.
150150
- Use [password best practices] for any account with access to PII,
151151
including developer accounts which have access to production.
152152
- Avoid using shared logins with access to PII, even if such logins are managed

0 commit comments

Comments
 (0)